Google Offers Advice on Secure Passwords

It's National Cyber Security Awareness Month, and Google wants to remind you of a basic tenet of online security: passwords. Considering that October started off with a security breach that struck more than 10,000 Hotmail accounts, a security review may not be such a bad idea. Michael Santerre, Google's Consumer Operations Associate detailed Google's password advice in a recent blog post.

By Ian Paul
Thu, October 08, 2009

PC World — It's National Cyber Security Awareness Month, and Google wants to remind you of a basic tenet of online security: passwords. Considering that October started off with a security breach that struck more than 10,000 Hotmail accounts, a security review may not be such a bad idea. Michael Santerre, Google's Consumer Operations Associate detailed Google's password advice in a recent blog post.

Slideshow: 10 Cool Things You Didn't Know About Google

Some of Santerre's precautions are things you've likely heard many times before: don't use personal information like your name or birth date, and don't use simple passwords like "password" or "letmein." Instead, Santerre says you should use a unique password for every site, one that includes a mixture of numbers, letters, and symbols. This will help protect you from dictionary attacks, where a hacker uses a program that tries millions of word and letter combinations to guess your password. But keeping track of so many passwords can be tough; Santerre advises you to write your secret codes down or keep them in a computer file, just don't give your file an obvious name like 'paswords.doc.' or 'Fort Knox.txt.'

Finally, keep your password recovery options up to date so that a hacker can't take over an abandoned e-mail account. Let's say your ilovegmail@gmail.com account uses ilovehotmail@hotmail.com as the secondary e-mail address for the password recovery option. If you've forgotten about that account, a hacker could sign up for ilovehotmail@hotmail.com and end up hacking into your Gmail account. This is exactly how a French hacker gained access to Twitter's company files earlier this year.

If you're worried about your password security, here are a few more tips:

1) Use a combination where you substitute letters for numbers, words for numbers and include random capitalization. For example, 19 Peach Place becomes 0ne9peacHpl!--note the random exclamation mark at the end.

2) Create a sentence and then pull the first letter from each word, substituting numbers or even symbols were possible. Turning a sentence like, "Zachary Taylor was the twelfth president of the United States," into ZTwt12potUS.

3) Use a random password generator. You can find several online like Strong Password Generator, and others are available in PC World's Downloads Section.

4) If you've chosen your own number, letter, and symbol combination, but aren't sure how strong it is, run it through Microsoft's Password Checker.

5) So now you've got a strong password for all your important e-mail and banking accounts, but how are you going to keep track of all of these endless codes? Consider using a password manager, or just keep them on a piece of paper in the physical world--just don't attach the list to your computer.

If you want more online security than just smart passwords, check out PC World's article on "Super-safe Web Browsing."

As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make to help achieve project success.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
3 minute Flash video - overview of the need for and value of Configuration Control.
Cloud deployments are playing a critical role in propelling innovation for many companies. At the same time security has become the #1 one of the top concerns for IT and business leaders as they migrate into the cloud. In this webinar, learn from Accenture discusses how to recast the cloud as a "fresh chance to rethink your approach to security."
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Sponsored Links
Resource Center